Malicious PDF — malware analysis report

Static analysis result for SHA-256 060ff38cbbc6e323…

MALICIOUS

PDF

18.0 KB Created: 2019-11-28 22:26:02 +00:00 Authoring application: mPDF 5.7
MD5: 186993904505ca7f3dd98714512f106e SHA-1: ee174253ddab704f31c246ef8a472137eba8e592 SHA-256: 060ff38cbbc6e3231717c974e1699d282c0c2ae0445b00880aa6c6e8aae47bcc
92 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The PDF contains a large number of embedded URLs pointing to external PDF files, as indicated by the PDF_SEO_LINK_FARM heuristic. While the URLs themselves are currently classified as benign, the sheer volume and structure suggest a malicious intent, possibly for SEO manipulation or to host further malicious content. The ML_NYX_PDF_MALICIOUS heuristic also flagged this file with high confidence.

Machine Learning

  • Nyx PDF Classifier malicious score 0.9807

Heuristics 2

  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL http://cefasfese.4pu.com/4733737736737732/The-Los-Angeles-Diaries-A-Memoir-by-James-Brown.pdf
    • http://cefasfese.4pu.com/4733737736739732/This-River-A-Memoir-by-James-Brown.pdf
    • http://cefasfese.4pu.com/2733733730734738/The-Bohemian-Love-Diaries-A-Memoir-by-Slash-Coleman.pdf
    • http://cefasfese.4pu.com/3734733731739736/The-Vanity-Fair-Diaries-1983-1992-by-Tina-Brown.pdf
    • http://cefasfese.4pu.com/3736732730734731/The-Adderall-Diaries-A-Memoir-of-Moods-Masochism-and-Murder-by-Stephen-Elliott.pdf
    • http://cefasfese.4pu.com/4734737734731/Kill-Em-and-Leave-Searching-for-James-Brown-and-the-American-Soul-by-James-McBride.pdf
    • http://cefasfese.4pu.com/4731739738731/Hammered-Memoir-of-an-Addict-by-Geoff-Brown.pdf
    • http://cefasfese.4pu.com/9730739739733736/Endgame-The-Complete-Training-Diaries-Endgame-The-Training-Diaries-1-3-by-James-Frey.pdf
    • http://cefasfese.4pu.com/3736738735739733/The-Confessions-and-Diaries-of-a-New-York-Veteran-of-the-Greenwich-Village-Stonewall-Inn-Raid-of-June-28-1969-Souvenirs-by-Scott-G-Brown.pdf
    • http://cefasfese.4pu.com/4739737731734/Leaving-Church-A-Memoir-of-Faith-by-Barbara-Brown-Taylor.pdf
    • http://cefasfese.4pu.com/9731730730733736/Existence-Endgame-The-Training-Diaries-3-by-James-Frey.pdf
    • http://cefasfese.4pu.com/4731731734733/The-Secret-Diaries-of-Charlotte-Bront-by-Syrie-James.pdf
    • http://cefasfese.4pu.com/2738737730734739/Pride-amp-Popularity-The-Jane-Austen-Diaries-1-by-Jenni-James.pdf
    • http://cefasfese.4pu.com/6739732737738732/Ancestral-Voices-Diaries-1942-1943-by-James-Lees-Milne.pdf
    • http://cefasfese.4pu.com/1730732738735731739/Ancient-as-the-Hills-Diaries-1973-1974-by-James-Lees-Milne.pdf
    • http://cefasfese.4pu.com/8734731735736732/A-Memoir-by-James-De-Veaux.pdf
    • http://cefasfese.4pu.com/4732736730738738/A-League-of-My-Own-Memoir-of-a-Pitcher-for-the-All-American-Girls-Professional-Baseball-League-by-Patricia-I-Brown.pdf
    • http://cefasfese.4pu.com/9738730734732732/Rita-Will-Memoir-of-a-Literary-Rabble-Rouser-by-Rita-Mae-Brown.pdf
    • http://cefasfese.4pu.com/6732733731730735/My-Regards-To-Broadway-A-Memoir-by-James-Fairfax.pdf
    • http://cefasfese.4pu.com/1731734737738737/Memoir-of-the-Hawk-by-James-Tate.pdf